2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65012MEDIUM5.4Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any...
CVE-2025-64515MEDIUM4.3Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data ...
CVE-2025-64325CRITICAL9Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious use...
CVE-2025-64324HIGH7.7KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos...
CVE-2025-62406HIGH8.8Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset ...
CVE-2025-54990MEDIUM5.3XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users with...
CVE-2025-63229MEDIUM5.4The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting ...
CVE-2025-63217CRITICAL9.8The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across dev...
CVE-2025-63216CRITICAL10The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across...
CVE-2025-63215HIGH7.2The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware u...
CVE-2025-12119LOW3.3A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-63228CRITICAL9.8The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vu...
CVE-2025-63227HIGH7.2The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne...
CVE-2025-63226MEDIUM5.7The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking...
CVE-2025-37162HIGH8.8A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduc...
CVE-2025-37161HIGH7.5A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacke...
CVE-2025-63955HIGH7.5A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record Syst...
CVE-2025-63749MEDIUM6.5pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.
CVE-2025-63693MEDIUM5.4The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping fo...
CVE-2025-63225CRITICAL9.8The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing au...
CVE-2025-61664MEDIUM4.9A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free iss...
CVE-2025-61663MEDIUM4.9A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (...
CVE-2025-61662HIGH7.8A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error wh...
CVE-2025-61661MEDIUM4.8A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootl...
CVE-2025-60455HIGH8.4Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvca...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now